Apply the steps in this tech-note after installing the latest updates 2018 (Update 13) and 2021 (Update 3) that were released on 17 Dec 2021
Overview
There are a couple of vulnerabilities that have been reported in Log4j CVE-2021-44228 (LogShell) and CVE-2021-45046 , which is a popular library. Adobe ColdFusion uses these libraries.
A new vulnerability CVE-2021-45105 was reported on 18th Dec 2021, which Apache addressed by releasing a newer version of Log4j (2.17.0). Even though Adobe ColdFusion uses this library, we did not find any exploitable attack vector or mechanism with Adobe ColdFusion.
As a best practice, we recommend that you upgrade the Log4j2 libraries to version 2.17.0.
Note: The zip packages all the updated jars for ColdFusion, Performance Monitoring Toolset, and API Manager.
UPDATE: To upgrade the Log4j 2.x jars to Log4j 2.17 jars, see this document .